IP Library Granted Patent US 12,015,689
Granted Patent B2
US 12,015,689 · App. 18/058,358 · Granted Jun 18, 2024

Container management for cryptanalysis attack protection

Inventors: Gabriel Zvi BenHanokh (Tel-Aviv, IL); Orit Wasserman (Mitzpe Aviv, IL)
Assignee: Red Hat, Inc.
H04L9/002G06F21/56
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,015,689
App. No.
18/058,358
Granted
Jun 18, 2024
Kind
B2
Abstract

Containers can be managed for cryptanalysis attack protection. For example, a computing system can receive, from a container, a description specifying a first hardware requirement for the container. The computing system can restrict access to hardware based on the first hardware requirement for the container. The computing system can perform, for a data object requested by the container, an encryption operation and a decryption operation using the hardware. A result of the encryption operation can be inaccessible to the container prior to the decryption operation.

Claims (53)

1. A system comprising:

a processor; and

a memory including instructions that are executable by the processor for causing the processor to:

receive, from a virtual machine, a description specifying a first hardware requirement for the virtual machine;

restrict access to hardware based on the first hardware requirement for the virtual machine; and

perform, for a data object requested by the virtual machine, an encryption operation and a decryption operation using the hardware, wherein a result of the encryption operation is inaccessible to the virtual machine prior to the decryption operation.

2. The system of claim 1 , wherein the memory further includes instructions that are executable by the processor for causing the processor to:

determine the virtual machine is safe based on the description specifying the first hardware requirement for the virtual machine; and

in response to determining the virtual machine is safe, assign the virtual machine to a first virtual machine group, wherein each virtual machine of the first virtual machine group is safe.

3. The system of claim 1 , wherein the virtual machine is a first virtual machine and the description is a first description and the memory further includes instructions that are executable by the processor for causing the processor to:

receive, from a second virtual machine, a second description specifying a second hardware requirement for the second virtual machine; and

determine the second virtual machine is unsafe based on the second description specifying the second hardware requirement.

4. The system of claim 3 , wherein the memory further includes instructions that are executable by the processor for causing the processor to:

assign the second virtual machine to a second virtual machine group, wherein each virtual machine of the second virtual machine group is unsafe; and

monitor the second virtual machine for a cryptanalysis attack by the second virtual machine.

5. The system of claim 4 , wherein the memory includes instructions that are executable by the processor for causing the processor to identify the cryptanalysis attack by determining a number of unsuccessful attempts made by the second virtual machine to access a data object exceeds a predefined number of unsuccessful attempts.

6. The system of claim 4 , the memory further includes instructions that are executable by the processor for causing the processor to:

determine the second virtual machine satisfies one or more predefined conditions; and

in response to determining the second virtual machine satisfies the one or more predefined conditions, assign the second virtual machine to the second virtual machine group.

7. The system of claim 6 , wherein the one or more predefined conditions comprise a geographic location associated with the second virtual machine.

8. The system of claim 3 , wherein the memory further includes instructions that are executable by the processor for causing the processor to, in response to determining the second virtual machine is unsafe, restrict the second virtual machine from performing execution operations.

9. A computer-implemented method comprising:

receiving, from a virtual machine, a description specifying a first hardware requirement for the virtual machine;

restricting access to hardware based on the first hardware requirement for the virtual machine; and

performing, for a data object requested by the virtual machine, an encryption operation and a decryption operation using the hardware, wherein a result of the encryption operation is inaccessible to the virtual machine prior to the decryption operation.

10. The method of claim 9 , further comprising:

determining the virtual machine is safe based on the description specifying the first hardware requirement for the virtual machine; and

in response to determining the virtual machine is safe, assigning the virtual machine to a first virtual machine group, wherein each virtual machine of the first virtual machine group is safe.

11. The method of claim 9 , wherein the virtual machine is a first virtual machine and the description is a first description and the method further comprises:

receiving, from a second virtual machine, a second description specifying a second hardware requirement for the second virtual machine; and

determining the second virtual machine is unsafe based on the second description specifying the second hardware requirement.

12. The method of claim 11 , further comprising:

assigning the second virtual machine to a second virtual machine group, wherein each virtual machine of the second virtual machine group is unsafe; and

monitoring the second virtual machine for a cryptanalysis attack by the second virtual machine.

13. The method of claim 12 , further comprising identifying the cryptanalysis attack by determining a number of unsuccessful attempts made by the second virtual machine to access a data object exceeds a predefined number of unsuccessful attempts.

14. The method of claim 12 , further comprising:

determining the second virtual machine satisfies one or more predefined conditions; and

in response to determining the second virtual machine satisfies the one or more predefined conditions, assigning the second virtual machine to the second virtual machine group.

15. The method of claim 14 , wherein the one or more predefined conditions comprise a geographic location associated with the second virtual machine.

16. The method of claim 11 , wherein the further comprising, in response to determining the second virtual machine is unsafe, restricting the second virtual machine from performing execution operations.

17. A non-transitory computer-readable medium comprising program code that is executable by a processor for causing the processor to:

receive, from a virtual machine, a description specifying a first hardware requirement for the virtual machine;

restrict access to hardware based on the first hardware requirement for the virtual machine; and

perform, for a data object requested by the virtual machine, an encryption operation and a decryption operation using the hardware, wherein a result of the encryption operation is inaccessible to the virtual machine prior to the decryption operation.

18. The non-transitory computer-readable medium of claim 17 , further comprising program code that is executable by a processor for causing the processor to:

determine the virtual machine is safe based on the description specifying the first hardware requirement for the virtual machine; and

in response to determining the virtual machine is safe, assign the virtual machine to a first virtual machine group, wherein each virtual machine of the first virtual machine group is safe.

19. The non-transitory computer-readable medium of claim 17 , wherein the virtual machine is a first virtual machine and the description is a first description further comprising program code that is executable by a processor for causing the processor to:

receive, from a second virtual machine, a second description specifying a second hardware requirement for the second virtual machine; and

determine the second virtual machine is unsafe based on the second description specifying the second hardware requirement.

20. The non-transitory computer-readable medium of claim 19 , further comprising program code that is executable by a processor for causing the processor to:

assign the second virtual machine to a second virtual machine group, wherein each virtual machine of the second virtual machine group is unsafe; and

monitor the second virtual machine for a cryptanalysis attack by the second virtual machine.

Assignments (2)
CHANGE OF NAME Recorded Mar 3, 2026
From: RED HAT, INC.
To: RED HAT, LLC
Reel/Frame 074913/0759 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 23, 2022
From: WASSERMAN, ORIT; BENHANOKH, GABRIEL ZVI
To: RED HAT, INC.
Reel/Frame 061862/0211 →